Re: Laptop - Full Disk Encryption? (Booting defeats FDE)



On 2007-10-23 Bill Stout wrote:
How to defeat full disk encryption: Boot up

Wow, you mean disk encryption won't protect from attack vectors it
wasn't designed to protect from in the first place? Big surprise here.
Not.

[...]
For protection of data on the computer _after_ it's running, you may
consider products that offer more granular file-level encryption like
Credant Technologies or Information Security Corp. These products
encrypt what's important (user files and temp files), but allow for
standard support, backup and recovery practices.

For protection of data on the computer _after_ it's running, you have a
kernel which implements and enforces access controls and privileges.

Besides, how do those file-level encryption systems make sure every kind
of temporary data an application may create on the disk is encrypted?
How do they ensure no unencrypted user data is left after the encryption
system is put in place? How do they handle paged data? How do they
handle (read "ensure confidentiality of") the keys?

Regards
Ansgar Wiechers
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq



Relevant Pages

  • Re: Securing data to a process principal
    ... reasonable controls that protect against "casual" abuse. ... hooks into your encryption function) and you cannot prevent an admin using ... The RM analyst also uses an app that has an embedded obfuscated key (I'll ... where the secret is stored in the registry. ...
    (microsoft.public.platformsdk.security)
  • Re: encrypted source file support in jdk?
    ... Encryption is a solution to a problem. ... You want to protect your source files. ... C++ with a highly optimising compiler will do ...
    (comp.lang.java.help)
  • Re: database password and encryption
    ... I know the basic concepts about encryption. ... This database should be encrypted with a strong, ... way you can protect the database AT ALL. ... I could encrypt the key several times and hide the new, resulting, keys on ...
    (microsoft.public.platformsdk.security)
  • Re: In Child Porn Case, a Digital Dilemma - USA
    ... and civil liberties against the government's responsibility to protect ... Department officials, meanwhile, have said that encryption is allowing ... compelling Sebastien Boucher, ... what he downloads to "clean out" the child porn, ...
    (uk.legal)
  • Encryptio key hardware solution... help :(
    ... that provides a Secure and Safe environment where these Credit Card ... Now it was proposed we do the 'hardware ... methods to protect and unprotect passed data. ... using a 2-step process the first step will need to read the encryption key ...
    (microsoft.public.sqlserver.security)